Wind River Support Network

HomeDefectsLIN10-5572
Fixed

LIN10-5572 : Security Advisory - python - CVE-2019-9947

Created: Mar 27, 2019    Updated: Aug 15, 2019
Resolved Date: Jul 16, 2019
Found In Version: 10.17.41.15
Fix Version: 10.17.41.17
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.2. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the query string or PATH_INFO) followed by an HTTP header or a Redis command. This is similar to CVE-2019-9740.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-9947 User=admin}

CVEs


Live chat
Online